PT-2019-7545 · Cjson · Cjson

Marco Grassi

·

Published

2019-04-29

·

Updated

2025-07-22

·

CVE-2016-10749

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions cJSON versions prior to 2016-10-02
Description The issue is related to a buffer over-read in the parse string function in cJSON.c. This occurs when processing a string that starts with a " character and ends with a character.
Recommendations For versions prior to 2016-10-02, update to a version released after 2016-10-02 to resolve the issue.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2016-10749

Affected Products

Cjson